MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
Published Sep 12, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.46%
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user with Developer-level access to cause a persistent denial of service affecting all users on a GitLab instance by uploading large files.
Affected products
-
- Version 18.2StatusaffectedConstraints<18.2.6
- Version 18.3StatusaffectedConstraints<18.3.2
- Version 7.8StatusaffectedConstraints<18.1.6
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 18.1.6, 18.2.6, 18.3.2 or above.
Weaknesses (1)
References (4)
- https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/ Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-29022 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/554062 issue-trackingpermissions-requiredBroken Link
- https://hackerone.com/reports/3161756 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/ | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-29022 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/554062 | issue-trackingpermissions-requiredBroken Link | |
| https://hackerone.com/reports/3161756 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Sep 12, 2025
Updated Sep 12, 2025
Reserved Jul 7, 2025
Link CVE-2025-7337
CISA Vulnrichment
Updated Sep 12, 2025
ENISA EUVD
EUVD-2025-29022 Assigner GitLab
Published Sep 12, 2025
Updated Sep 12, 2025
Exploited since n/a
Link EUVD-2025-29022